ThebinderLab

/ Trust

Trust & Security

This page is maintained by ThebinderLab to answer common security and privacy questions about our shop. It describes current practices and is not an independent certification.

Shared responsibility

ThebinderLab AB operates the storefront and is responsible for how we collect and handle your data. Our hosting and database providers run the underlying infrastructure. You are responsible for keeping your account credentials safe.

Payments

All card payments are processed by Stripe. We never see or store full card numbers, CVCs, or bank credentials. Stripe is PCI-DSS Level 1 certified.

Data in transit and at rest

The site is served over HTTPS. Customer and order data is stored in a managed Postgres database with encryption at rest provided by our hosting partner.

Access control

Customer-facing data is protected by row-level security policies in our database, so users only access their own orders and account information. Administrative access is limited to a small number of ThebinderLab staff.

Subprocessors

We share data only with the processors we need to run the shop: Stripe (payments), Resend (transactional email), our print and shipping partners, and our hosting / database provider. We do not sell personal data.

Cookies and analytics

Strictly necessary cookies are always on. Analytics and marketing cookies only run after you consent via our cookie banner.

Retention and deletion

Order and tax records are retained for 7 years to meet Swedish legal requirements. Marketing opt-ins are kept until you unsubscribe. See our Privacy Policy for full details and how to request deletion.

Report a vulnerability

If you believe you have found a security issue, please email security@thebinderlab.com. We appreciate responsible disclosure and will respond as quickly as we can.